Skip to content
Cyber Science Lab

A Federated Learning Approach for Multi-stage Threat Analysis in Advanced Persistent Threat Campaigns

Multi-stage threats like advanced persistent threats (APT) pose severe risks by stealing data and destroying infrastructure, with detection being challenging due to their stealthy behaviour and the need to correlate weak signals across a campaign’s many stages. This paper proposes a novel three-phase unsupervised federated learning framework that identifies unique log event types, extracts suspicious patterns from related log events, and orders them by complexity and frequency to detect APT activity. The framework combines federated learning with Paillier partial homomorphic encryption so that participating organisations can collaboratively train a detection model without exposing their raw log data, addressing the privacy constraints that limit multi-client threat-detection research under regulations like GDPR. Evaluated on the SoTM 34 dataset, the framework compares favourably against traditional methods, efficiently extracting and analysing suspicious patterns from log files, reducing analyst workload, and maintaining data privacy throughout.